Skip to content

Recovery Planning

This template is the starting point for the recovery planning your organization owns for the cloud service offering: the recovery objectives you commit to, the backup and recovery capability that has to meet them, the recovery plan itself, and the testing that proves the capability works. Recovery is executed by your infrastructure and operations teams against your own environment. Fill in the sample sections with your real objectives, mechanisms, and test schedule, then keep the objectives and the plan in step as the offering changes.

Quick Summary

A client-fillable template covering the recovery objectives, backup alignment, recovery plan, and recovery testing the provider of the offering owns. It carries sample text you replace with your real practice, the four KSI-RPL statements it answers, and a table of how the platform evidences each practice. Every one of the four indicators is a standing review or test, so each needs a real cadence in the Organization-Defined Values table.

Customer-owned template

This is a starting-point template delivered with GRC-ITSM. The practices it describes are owned and executed by your organization, not by the platform. Fill the Organization-Defined Values, remove framework rows you are not pursuing, and adopt it as your own document before relying on it.

Related documentation

Download the KB article (Markdown)


Requirements this document answers

All four are Key Security Indicators in the Recovery Planning family. No FedRAMP Rule (FRR) in the 2026 Consolidated Rules names a recovery document; the obligation is the KSI outcome.

KSI Name Statement
KSI-RPL-RRO Reviewing Recovery Objectives The desired Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and persistently reviewed for alignment with the provider's business needs and capabilities.
KSI-RPL-ABO Aligning Backups with Objectives The alignment of machine-based information resource backups with defined recovery objectives is persistently reviewed.
KSI-RPL-ARP Aligning Recovery Plan The alignment of recovery plans with defined recovery objectives is persistently reviewed.
KSI-RPL-TRC Testing Recovery Capabilities The capability to recover from incidents and contingencies aligned with defined recovery objectives is persistently tested.

"Persistently" is the operative word in all four: each of these is a standing review or test, not a one-time exercise. Set a cadence in the Organization-Defined Values table and hold it.


Sample practice: recovery objectives

Sample text. [Organization] defines recovery objectives per service tier. Tier 1 services, which carry federal customer data in the production path, hold an RTO of [duration] and an RPO of [duration]. Tier 2 services hold an RTO of [duration] and an RPO of [duration]. The objectives are set by [role] with [business owner role], and are derived from [basis: customer commitments, contractual SLAs, business impact analysis]. They are reviewed [cadence] and on any material change to the offering's architecture or customer commitments. The review asks two questions: do these objectives still match what the business needs, and can the current capability actually meet them.

Replace with your practice. State real numbers per tier, name the basis, and name who signs off. An objective nobody can meet is worse than a longer objective you can.


Sample practice: backups aligned to the objectives

Sample text. Machine-based information resources are backed up by [mechanism] on a [frequency] schedule, with [retention] retention and copies held in [locations, including a second region or availability zone]. Backup coverage is reconciled against the asset inventory [cadence] so that a resource added to the environment does not sit outside the backup scope. Restore integrity is verified by [verification method] on a [cadence] sample. The reconciliation report states, per tier, the achieved recovery point against the declared RPO and flags any resource whose backup frequency cannot meet its tier's objective.

Replace with your practice. Name the mechanism, the frequency, the retention, and where copies live. The alignment claim in KSI-RPL-ABO is the comparison between achieved and declared, so make sure something produces that comparison.


Sample practice: the recovery plan

Sample text. The [Offering] recovery plan is held at [location] and covers: the recovery sequence by service tier and dependency order, the roles and the activation authority, the alternate processing and storage arrangements, the communications path to agency customers, and the criteria for declaring recovery complete. Each recovery procedure states the objective it serves and the elapsed time it has been observed to take, so a procedure that has drifted past its RTO is visible in the plan itself. The plan is reviewed [cadence] by [role], and after every recovery test and every actual recovery event.

Replace with your practice. Link the real plan. The alignment claim in KSI-RPL-ARP is between plan and objectives, so the plan needs to carry the objectives it serves rather than reference them elsewhere.


Sample practice: recovery testing

Sample text. Recovery capability is tested on a [cadence] schedule. The test program includes [test types: tabletop, functional exercise, full failover, restore-from-backup sampling], scoped so that every Tier 1 service is exercised at least [frequency]. Each test records the scenario, the participants, the measured recovery time and recovery point, the objectives they were compared against, the deficiencies found, and the corrective actions with owners and due dates. Corrective actions are tracked to closure through [tracking mechanism]. Tests that miss an objective trigger either a capability change or an objective change; the plan does not stay in a state where the test and the objective disagree.

Replace with your practice. Name the test types and cadence, and name where the after-test corrective actions are tracked. Recording the measured time against the objective is what makes the test evidence rather than an attendance record.


Organization-defined values

Value Setting Notes
Service tiers in scope [tiers] Drives per-tier objectives
RTO per tier [durations] KSI-RPL-RRO
RPO per tier [durations] KSI-RPL-RRO
Basis for the objectives [BIA, contractual SLA, customer commitment] KSI-RPL-RRO
Objective review cadence [cadence] KSI-RPL-RRO, "persistently"
Backup mechanism and frequency [mechanism; frequency per tier] KSI-RPL-ABO
Backup retention and copy locations [retention; locations] KSI-RPL-ABO
Backup coverage reconciliation cadence [cadence] KSI-RPL-ABO
Restore verification method and cadence [method; cadence] KSI-RPL-ABO
Recovery plan location [location] KSI-RPL-ARP
Recovery plan review cadence [cadence] KSI-RPL-ARP
Recovery test types [types] KSI-RPL-TRC
Recovery test cadence [cadence] KSI-RPL-TRC
Corrective action tracking mechanism [mechanism] KSI-RPL-TRC
Activation authority [role] Named in the plan
Document owner [role] Fills the authority section

Evidence

The GRC-ITSM platform does not run your backups, hold your recovery plan, or execute your failover. It evidences that the four Recovery Planning indicators are being met, through scheduled machine checks and validation records. See the Continuous Monitoring and Reporting Policy and Procedures for the validation tree and the check cadences.

Practice What the platform records
Objectives defined and reviewed (KSI-RPL-RRO) Validation runs on the objective review, with the review as a recurring compliance task
Backup alignment (KSI-RPL-ABO) Validation runs from scheduled checks on backup coverage, frequency, and achieved recovery point against the declared RPO
Plan alignment (KSI-RPL-ARP) Validation runs on the plan review, with the plan as a Component record of type Plan
Recovery testing (KSI-RPL-TRC) Validation runs per test, carrying measured recovery time and pass or fail against the objective; deficiencies open Issues tracked to closure

The recurring compliance task program already carries contingency plan functional exercise testing, contingency plan training, and the annual contingency plan review as scheduled tasks. Those tasks are where your test and review outcomes land as dated evidence.


Authority, review, and revision

Client fills. Name the executive who issues this document, the role that owns the recovery plan, the review cadence, and the approval path for exceptions to the objectives. Record the issue date and the revision history below.

Version Date Author Change
[0.1] [date] [author] Initial draft from template